2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-7193——PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery...
CVE-2008-7192——Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3....
CVE-2008-7191——Unspecified vulnerability in Polipo before 1.0.4 allows remote attackers to cause a denial of service (crash) via a long...
CVE-2008-7190——Unspecified vulnerability in Adium before 1.2 has unknown impact and attack vectors related to javascript: URLs, possibl...
CVE-2008-7189——Multiple unspecified vulnerabilities in Local Media Browser before 0.1 have unknown impact and attack vectors related to...
CVE-2008-7188——ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the pr...
CVE-2008-7187——Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to in...
CVE-2008-7186——Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain se...
CVE-2008-7185——GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlis...
CVE-2008-7184——Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web s...
CVE-2008-7183——PHP remote file inclusion vulnerability in eva/index.php in EVA CMS 2.3.1, when register_globals is enabled, allows remo...
CVE-2008-7182——Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote au...
CVE-2008-7181——Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter ...
CVE-2008-7180——del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request wit...
CVE-2008-7179——OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMI...
CVE-2008-7178——Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a...
CVE-2008-7177——Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, ...
CVE-2008-7176——Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. ...
CVE-2008-7175——Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress ...
CVE-2008-7174——Multiple buffer overflows in the Jura Internet Connection Kit for the Jura Impressa F90 coffee maker allow remote attack...
CVE-2008-7173——The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged ...
CVE-2008-7172——Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote...
CVE-2008-7171——Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inje...
CVE-2008-7170——GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to ex...
CVE-2008-7169——SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute ar...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now